{"api_version":"1","generated_at":"2026-07-24T20:50:00+00:00","cve":"CVE-2018-14774","urls":{"html":"https://cve.report/CVE-2018-14774","api":"https://cve.report/api/cve/CVE-2018-14774.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-14774","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-14774"},"summary":{"title":"CVE-2018-14774","description":"An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. When using HttpCache, the values of the X-Forwarded-Host headers are implicitly set as trusted while this should be forbidden, leading to potential host header injection.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-08-03 17:29:00","updated_at":"2018-10-17 17:05:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"https://symfony.com/blog/cve-2018-14774-possible-host-header-injection-when-using-httpcache","name":"https://symfony.com/blog/cve-2018-14774-possible-host-header-injection-when-using-httpcache","refsource":"CONFIRM","tags":["Patch","Third Party Advisory"],"title":"CVE-2018-14774: Possible host header injection when using HttpCache (Symfony Blog)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/symfony/symfony/commit/725dee4cd8b4ccd52e335ae4b4522242cea9bd4a","name":"https://github.com/symfony/symfony/commit/725dee4cd8b4ccd52e335ae4b4522242cea9bd4a","refsource":"CONFIRM","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"[HttpKernel] fix trusted headers management in HttpCache and InlineFr… · symfony/symfony@725dee4 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-14774","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-14774","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"14774","vulnerable":"1","versionEndIncluding":"2.7.48","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sensiolabs","cpe5":"symfony","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"14774","vulnerable":"1","versionEndIncluding":"2.8.43","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sensiolabs","cpe5":"symfony","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"14774","vulnerable":"1","versionEndIncluding":"3.3.17","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sensiolabs","cpe5":"symfony","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"14774","vulnerable":"1","versionEndIncluding":"3.4.13","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sensiolabs","cpe5":"symfony","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"14774","vulnerable":"1","versionEndIncluding":"4.0.13","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sensiolabs","cpe5":"symfony","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"14774","vulnerable":"1","versionEndIncluding":"4.1.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sensiolabs","cpe5":"symfony","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-14774","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. When using HttpCache, the values of the X-Forwarded-Host headers are implicitly set as trusted while this should be forbidden, leading to potential host header injection."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://github.com/symfony/symfony/commit/725dee4cd8b4ccd52e335ae4b4522242cea9bd4a","refsource":"CONFIRM","url":"https://github.com/symfony/symfony/commit/725dee4cd8b4ccd52e335ae4b4522242cea9bd4a"},{"name":"https://symfony.com/blog/cve-2018-14774-possible-host-header-injection-when-using-httpcache","refsource":"CONFIRM","url":"https://symfony.com/blog/cve-2018-14774-possible-host-header-injection-when-using-httpcache"}]}},"nvd":{"publishedDate":"2018-08-03 17:29:00","lastModifiedDate":"2018-10-17 17:05:00","problem_types":["CWE-20"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":7.2,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*","versionStartIncluding":"2.8.0","versionEndIncluding":"2.8.43","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*","versionStartIncluding":"3.3.0","versionEndIncluding":"3.3.17","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*","versionStartIncluding":"3.4.0","versionEndIncluding":"3.4.13","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0.0","versionEndIncluding":"4.0.13","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*","versionStartIncluding":"4.1.0","versionEndIncluding":"4.1.2","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*","versionStartIncluding":"2.7.0","versionEndIncluding":"2.7.48","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"14774","Ordinal":"131482","Title":"CVE-2018-14774","CVE":"CVE-2018-14774","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"14774","Ordinal":"1","NoteData":"An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. When using HttpCache, the values of the X-Forwarded-Host headers are implicitly set as trusted while this should be forbidden, leading to potential host header injection.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"14774","Ordinal":"2","NoteData":"2018-08-03","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"14774","Ordinal":"3","NoteData":"2018-08-03","Type":"Other","Title":"Modified"}]}}}